-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Sat, 01 Aug 2026 13:42:11 +0200
Source: libssh
Binary: libssh-4 libssh-4-dbgsym libssh-dev
Architecture: arm64
Version: 0.11.5-0+deb13u1
Distribution: trixie-security
Urgency: medium
Maintainer: arm64 Build Daemon (arm-conova-03) <buildd_arm64-arm-conova-03@buildd.debian.org>
Changed-By: Martin Pitt <mpitt@debian.org>
Description:
 libssh-4   - tiny C SSH library (OpenSSL flavor)
 libssh-dev - tiny C SSH library - Development files (OpenSSL flavor)
Closes: 1127693 1142537
Changes:
 libssh (0.11.5-0+deb13u1) trixie-security; urgency=medium
 .
   * New upstream security/bug fix release 0.11.4:
     - CVE-2026-0964: SCP Protocol Path Traversal in ssh_scp_pull_request()
     - CVE-2026-0965: Possible Denial of Service when parsing unexpected
       configuration files
     - CVE-2026-0966: Buffer underflow in ssh_get_hexa() on invalid input
     - CVE-2026-0967: Specially crafted patterns could cause DoS
     - CVE-2026-0968: OOB Read in sftp_parse_longname()
     - CVE-2026-3731: Read buffer overrun when handling SFTP extensions
     - Note: CVE-2025-14821 is Windows specific, does not apply to Linux
     https://www.libssh.org/2026/02/10/libssh-0-12-0-and-0-11-4-security-releases/
     (Closes: #1127693)
   * New upstream security/bug fix release 0.11.5:
     - CVE-2026-15370: Stack buffer overflow in SFTP server longname
       construction
     - CVE-2026-59843: Denial of service via zero advertised channel packet
       size
     - CVE-2026-59844: Denial of service via oversized SFTP read length
     - CVE-2026-59845: Denial of service via unchecked ProxyCommand fork()
       failure
     - CVE-2026-59846: Information disclosure via ProxyCommand %r username
       expansion
     - CVE-2026-59847: Integrity downgrade via OpenSSL AES-GCM tag verification
     - CVE-2026-59848: Denial of service via SFTP responses with unknown
       request IDs
     - CVE-2026-59849: Denial of service via automatic certificate
       authentication loop
     - CVE-2026-59850: Use-after-free via data callbacks on closed channels
     - Zero-initialize every ssh_string
     https://www.libssh.org/2026/07/21/libssh-0-12-1-and-0-11-5-security-releases/
     (Closes: #1142537)
Checksums-Sha1:
 556d3be997fc3f16eb16cc5b66cd8625d508b4ab 572732 libssh-4-dbgsym_0.11.5-0+deb13u1_arm64.deb
 2e7722d8ae134a5838a91b8e06f589e44445e7e5 199476 libssh-4_0.11.5-0+deb13u1_arm64.deb
 3a9089f2ae40896b8932a849abc1aa6cd94555d6 267668 libssh-dev_0.11.5-0+deb13u1_arm64.deb
 cd3042030a1ea84102e087369cd0066a73e0f4d3 8851 libssh_0.11.5-0+deb13u1_arm64-buildd.buildinfo
Checksums-Sha256:
 bd8243ed5a4762665f8c0bf8c31678feffa86530f97efd7a2d3c3fa46482fd61 572732 libssh-4-dbgsym_0.11.5-0+deb13u1_arm64.deb
 bc70c157a3850050e256d293be0e5a851b1f98ae6dd4e31b2c7d237b670eb1c9 199476 libssh-4_0.11.5-0+deb13u1_arm64.deb
 dfa8f2256e0a019ee22bd708293e427128524f65aefc14e34c4edd132afc3f4d 267668 libssh-dev_0.11.5-0+deb13u1_arm64.deb
 5b2cc331e8a5250706ed24979f90afde573e74abfacca3b186be058fa8232e61 8851 libssh_0.11.5-0+deb13u1_arm64-buildd.buildinfo
Files:
 48660905b71e21c161850b7d023b7447 572732 debug optional libssh-4-dbgsym_0.11.5-0+deb13u1_arm64.deb
 8ee964d820fdcd35bb89d813cf32bb13 199476 libs optional libssh-4_0.11.5-0+deb13u1_arm64.deb
 47bc35d084357164a34ad038df661141 267668 libdevel optional libssh-dev_0.11.5-0+deb13u1_arm64.deb
 43834792285c690a32594eb5366e9308 8851 libs optional libssh_0.11.5-0+deb13u1_arm64-buildd.buildinfo

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEElFiH1oZRZh1t4FSiXVp1sEH/1mIFAmpuUAkACgkQXVp1sEH/
1mLRoQ//Rg2LmZiA3pFhkOmQyUSKXJ2mhDfMm6fuou3YdMXqq9JTgM4Bvlpb9yIj
txwT0fKLNzt2ZIQOuhL0Wsn9FMPc98IVfA5hpQw/jU2ncQBS0+tYXkgvT+2Ab+3s
y33Hsu4w0UbXkJd2slJCm06egjByV/FLhv/x5Vf73VJJda330X5Loep0V8gvtMQh
BVD9UahzZVnUzZMFxTgs+uldOVLqooASB+xReM/RCFOaeGDHuQB9JadVSD/ORqdo
WM85In5f2EOt9Dr10NlNmU0unesWt40EwP6tG9BLUYTNEz+yk3sGtgGvlwv/GzfW
/Tas4mRTRNptqJXgwHwPuEYp3Zpyc+HNof1b3nGJShHPiOz3ugJukf2yYBovW8p4
BcGM7c2rYaO7p+p3yFnYa3L08quIVckHGmbZr5EwJTgY+H6VagjN3xTedMfA6UZS
nMZfGpmcMk0RROd/eKXU7c7rpn71wDpuaCavkhw6/A7DGJAcPxxW8nwKbspfq6Kp
jopnnxB+UhnlbjmJECer1bcRlylkqG+12wPl0aSN3lhg1UJfeXMDmAN8Nl62mVQ9
AGM7oSlSMAM4L5vx1iLDW1eoIFqZHasTOwEzhfqSjO+GtdEAD6rI/JbrZZ9v+Pcf
mw18J/xEG9+yg0GrflA1gPbi9l7wOK0wCASi8l/aHlTGb/Ye2Jo=
=gesi
-----END PGP SIGNATURE-----
